Consumer AI agents are colliding with a practical problem: many websites are blocking them, making it harder for tools like Meta’s Muse and OpenAI’s Dots to complete real-world tasks such as shopping, booking, and reservations. The dispute matters because it could slow the shift from chatbots that answer questions to agents that actually act for users.
What looks like a simple technical hiccup is quickly becoming a major test for the future of online commerce. As more people ask AI systems to buy groceries, reserve tables, or book flights, websites are responding with bot checks, anti-fraud systems, new restrictions, and in some cases deliberate blocks.
That tension is now spreading across retail, travel, restaurants, and review platforms, exposing an awkward truth: the web was built for people and ordinary software, not for a new layer of software acting on behalf of people.
What is happening to AI agents on the web?
AI agents are increasingly being turned away at the digital door. In recent weeks, users have reported that agents fail when they try to browse products, fill carts, or complete purchases on major consumer sites. In some cases, the block is intentional. In others, the agent is caught by security systems designed to stop spam, scraping, and fraudulent automation.
The result is confusing for consumers, because the error message often does not explain whether the site is rejecting the agent on purpose or whether a routine human-verification step simply broke the transaction. From the user’s perspective, the failure can look the same either way: the task doesn’t get done.
Meta’s Muse has become one of the most visible examples. The agent is designed to perform practical tasks for users rather than simply respond in a chat window. But users have reported that it can be stopped mid-task by retail sites, including some of the biggest names in e-commerce.
Why this matters now
This matters because AI agents are being pitched as the next major consumer computing interface. If the systems cannot reliably interact with the services people actually use, their value drops sharply. Booking a flight or ordering a product is not useful if the agent gets blocked halfway through checkout.
The problem also raises a broader question about the internet’s next phase: who gets to decide which software can act for a consumer online? That question is pushing companies, standards bodies, and infrastructure providers toward new rules for agent traffic.
How websites are blocking AI agents
Websites are using a mix of methods to stop or limit agent activity. Some platforms have updated their policies to explicitly bar unauthorized automation. Others rely on traditional anti-bot systems that look for suspicious behavior and trigger human verification challenges. Still others may be affected indirectly by technical changes in internet infrastructure, such as crawler controls or ad-related filtering policies.
For consumers, the distinction between these approaches is often invisible. A checkout failure or a failed sign-in can feel like the website itself is rejecting the request, even when the real cause is a security check or a default bot filter.
| Company / Platform | Reported stance on AI agents | What users are seeing | Notes |
|---|---|---|---|
| Amazon | Blocked Meta’s Muse from retail browsing and purchasing | Agent can no longer shop on the site | One of the clearest public examples of deliberate blocking |
| Walmart | Partnered with Muse, but not all access issues are intentional | Human-verification prompts can interrupt agent tasks | Company says it wants to be reachable through AI agents |
| Delta Air Lines | No third-party agent booking integration | Users report failed booking attempts | Carrier says security and customer experience come first |
| United Airlines | Policy restricts automated use without permission | Agent requests may be refused | Terms of use prohibit robots and similar tools without written approval |
| Yelp | Requires paid access for non-human traffic | Agent use for quotes and reservations often fails | Formal licensing is needed for automated access |
Who is blocking agents — and who is trying to work with them?
Some companies are drawing clear boundaries, while others are trying to adapt. The divide reflects different business models, risk tolerances, and views of what agent traffic means for security, advertising, and customer relationships.
Amazon’s move set off the latest wave of complaints
Amazon recently blocked Meta’s Muse from using its retail site, cutting off the agent’s ability to browse products or make purchases from the marketplace. That action turned a scattered set of frustrations into a more visible debate about whether major websites should allow consumer AI agents at all.
Amazon’s move also highlighted the power imbalance at the center of the issue. Agents are built to help consumers, but they still need permission from the services those consumers want to use. Without that permission, the agent’s usefulness disappears.
Walmart says it is open to agent-based shopping
Walmart, by contrast, says it wants to serve customers wherever they are, including inside AI agent experiences. The company is an official partner of Meta’s Muse, having been announced as one at Meta’s Connect developer conference in September.
But even there, technical friction remains. Users have reported being caught by human-verification prompts, which can fail if the process is interrupted before completion. That does not appear to be an intentional policy block, but the result can still be the same: the task stops.
Meta said it believes a business that turns away a personal agent is effectively turning away the customer behind it, and argued that the better path is to work with companies on clear rules instead of shutting agents out entirely.
That philosophy underpins Meta’s push for formal partnerships and new standards. The company has made it clear that it sees agent access as a business relationship problem as much as a technical one.
Why airlines are especially cautious
Airlines are among the most sensitive businesses in the emerging agent economy because they handle high-value transactions, changing inventory, customer identity verification, and fraud risk. A mistaken booking or unauthorized payment can create expensive support issues and compliance headaches.
That is why many travel companies are taking a guarded approach. Flight booking is one of the clearest use cases for agents, but it is also one of the hardest to implement safely.
What Delta says
Delta says it is taking steps to protect customers from unauthorized automated activity. The company says that if it ever opens up to AI agents, the move would need to be designed with security and the customer experience in mind.
Delta also said it does not currently have a partnership or integration that would let a third-party AI agent shop for or book flights on a customer’s behalf through its digital platforms. At the same time, the airline said it is still evaluating how external agents might fit into future customer interactions.
What United’s policy means
United has taken a more legalistic route, pointing users to its Terms of Use, which bar robots, spiders, and similar automated tools from monitoring or copying the site, or using it for unauthorized purposes, without prior written permission.
That language does not explicitly name modern consumer AI agents, but it gives the airline a basis to reject them if it chooses. In practice, that makes broad agent access unlikely without a formal arrangement.
How widespread is the problem?
The issue appears to be broader than one company or one product. Social media complaints have mentioned a range of brands and services where agents reportedly fail or are blocked, including Yelp, eBay, Zillow, Pizza Hut, Adidas, and multiple airlines.
Some users say the problem has intensified recently, suggesting a broader crackdown or a change in how security systems are treating agent-like traffic. Others believe the rise in consumer AI use simply makes long-standing anti-bot defenses more visible.
- Retailers are worried about scraping, fraud, and unauthorized purchasing.
- Travel companies are focused on identity checks and booking integrity.
- Review and reservation platforms are trying to protect data and paid access models.
- Consumers want convenience but often cannot tell why an agent fails.
eBay’s narrower approach
eBay says it is not trying to ban all third-party shopping agents. Instead, the company says its policies target unauthorized agents and activities such as automated scraping and model training.
That distinction matters. A company can be open to some kinds of agent use while still drawing a hard line around bulk data extraction or automated actions that violate platform rules.
Yelp’s paywall for bots
Yelp says non-human traffic is not permitted unless the agent has paid for access through its data licensing program. In practical terms, that means agents that try to pull a quote, join a waitlist, or book a table without a formal agreement are likely to fail.
Yelp’s position shows another possible future for the web: access for agents may be allowed, but only through commercial arrangements that treat agent traffic like a licensed data product rather than ordinary browsing.
What role is Cloudflare playing?
Cloudflare is part of the story because it sits in the infrastructure layer between websites and the traffic trying to reach them. The company offers tools that can help block or manage AI bots, and some observers think changes in its defaults may be affecting personal agents such as Muse.
One theory circulating among developers and users is that a September 15 change to crawler defaults altered how some sites treat AI traffic, especially pages that include ads. Under that setup, sites that were already configured to block AI bots for security reasons may have ended up blocking AI agents more broadly.
Cloudflare, however, says it does not have specific data to share about Muse or similar services at this time. Instead, it points to Cloudflare Radar, its public data hub, which shows rising bot activity but does not separate beneficial agent traffic from harmful automation.
Cloudflare’s own business incentives also matter. The company now operates a marketplace in which AI bots must pay for the data they access, and it has begun testing a browser built specifically for AI agents. That makes it both an infrastructure gatekeeper and a commercial participant in the agent economy.
How is the industry responding?
Industry players are increasingly trying to solve the trust problem before it hardens into a platform war. Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon have all begun working on an open standard for agent-to-business communication focused on online commerce.
The goal is to make it easier for websites to distinguish between legitimate agents acting for consumers and malicious bots attempting fraud, scraping, or spam. In effect, the industry wants a common language that websites can trust.
Meta says the idea is to create a path that works for both users and businesses: clearer norms, more predictable controls for companies, and ultimately a more efficient way for agents and services to interact.
That is an ambitious goal, because it asks competing companies to agree on how software should identify itself, what permissions it needs, and when a site should allow a transaction to proceed. But the alternative is a fragmented web where every site invents its own agent rules.
Why standards may matter more than partnerships alone
Partnerships can solve access problems one company at a time, but standards can scale. If every major service requires a separate integration, agents may become little more than silo-specific assistants. A common protocol would let more businesses participate without rebuilding the same technical plumbing over and over again.
For consumers, that could mean fewer failed checkouts and less uncertainty about whether an agent can complete a task. For businesses, it could mean tighter control over authentication, rate limits, and acceptable use.
The consumer experience problem
At the center of all of this is the user, who often only sees the final failure. The person asks an agent to order dinner, reserve a table, or buy a pair of shoes, and the assistant stalls out at the security check.
That makes the current generation of agents feel less reliable than the marketing suggests. It also risks blaming the wrong party. A user may assume the agent is broken, when the site is the one rejecting the request. Or the user may assume the site is acting in bad faith, when the real issue is a protection system misclassifying an automated helper as a harmful bot.
This confusion is one reason the agent market may need more transparency. Without clearer messages about why a transaction failed, consumers will continue to bounce between frustration with the website and frustration with the AI tool.
What happens next?
The near future of consumer AI agents likely depends on three things: whether major websites choose to open their doors, whether common standards emerge, and whether technical identity systems can prove that an agent is acting on behalf of a real user.
If those pieces come together, agents could become a normal layer of online commerce. If they do not, the web may remain a patchwork of exceptions, with some services welcoming agents, some limiting them, and others blocking them outright.
For now, the story is less about flashy AI capability than about permission. AI agents can only deliver on their promise if the web lets them act.
Key developments at a glance
| Date | Event | Why it matters |
|---|---|---|
| September 2026 | Meta announced new Muse partners at Connect | Showed that some retailers want to support agent-based shopping |
| September 15, 2026 | Cloudflare crawler default change | May have affected how some sites handle AI-related traffic |
| Late September 2026 | Users reported agent failures on multiple brands | Signaled that access problems were becoming more common |
| October 5, 2026 | Walmart complaints spread on social media | Highlighted consumer confusion over human checks and agent blocks |
| October 6, 2026 | Industry partners pushed an open commerce standard | Suggested a coordinated effort to define agent access rules |
The battle over AI agents is no longer just about how smart they are. It is about whether the internet’s biggest businesses are willing to treat them as legitimate representatives of customers — and if not, whether a new standard can make that possible.









